The Threat: Attackers are impersonating IT staff, election officials, and other trusted contacts by phone, email, text, and Microsoft Teams to steal user credentials or take control of a user's device.
Immediate Action: Pause for nine seconds before acting on any request (i.e., Take9). Never share a password or MFA code. Never install software or approve screen sharing because of an unexpected call or message. Verify the request by calling back or reaching out through another mechanism you already know, otherwise known as out-of-band verification.
Stay Alert: These scams are convincing and increasing year-over-year. Talk with your team, including temporary and seasonal staff, and report questionable contact right away.
What happened
The Center for Internet Security recently reported that cyber actors are actively targeting state and local election officials through phishing and other social engineering tactics, including fake requests to steal passwords, credentials, or other sensitive information. While these tactics are not new, the election community should be on the lookout for suspicious requests and remain vigilant, even when outreach comes from someone you trust: your IT help desk, a colleague, or an official election office.
The advisory also noted targets beyond election offices, such as fake websites asking voters to verify their information, emails claiming to be election office updates that direct candidates to a malicious site, and impersonation of IT and help desk personnel through Microsoft Teams. Both Microsoft and Sophos have documented malicious attempts using Microsoft Teams.
Social engineering and phishing attacks have different names. But they all use a similar trick, where someone pretends to be someone your office trusts, delivered through different channels:
Phishing: By email. A message that looks like it comes from a colleague or another official asking you to click a link, open an attachment, or log into a fake page.
Vishing: By voice. A phone or Teams call from someone claiming to be IT support, an election office, or a vendor tries to talk you into sharing credentials or granting access.
Smishing: By text message. A short or casual text usually with a link.
Why this matters
These attacks don’t always land in your email inbox, and major security firms report that non-email attack vectors are increasing. Fraudulent requests also arrive as a phone call, a text, or a Teams chat. And when attackers pose as an election office to contact voters or candidates, the damage isn’t just stolen information. It also chips away at public trust and accurate information your office puts out.
Election officials should know what to watch out for:
Requests for passwords or codes: No legitimate organization will ever ask for your password or MFA code by phone, email, or chat. If anyone does that, immediately disengage and report it.
Messages posing as your office: Emails, calls, or texts to voters, candidates, or staff that look like they came from your office and link to a lookalike website asking people to “verify” their information. Ensure people know your official website and verified accounts; the best way to do this is to have an official .gov website.
Urgency and pressure: You may be pressured or asked to act urgently, such as “act now,” “your account is locked,” or “the director needs this today.” Often, manufactured urgency is a key tell. Take9 puts it plainly: pause nine seconds before you act on a message that wants you to move fast.
Familiar voices: Artificial intelligence can clone a real person’s voice with only seconds of data, and caller ID can be faked or masked. A voice alone should not be proof. Verify through another channel you trust.
Unexpected IT or help desk contact: A call or Teams message from someone claiming to be IT or help desk personnel, asking you to install software or share your screen. Legitimate IT does not ask for this out of the blue. Hang up and call your real IT contact directly.
Unexpected vendor or election office requests: Outreach from a vendor or state election official asking to gain access to internal systems or requesting you to log in to their portal or reset your password. Similarly, hang up and contact them directly.
These are the same patterns we walked through in the Situation Room of our July 29 newsletter. Regardless of the method (i.e., call, text, email, etc), defense is generally the same.
What to do now
These steps are recommended by CISA, CIS, and the Election Security Exchange to help election officials remain vigilant and counter impersonation attacks.
Take 9 seconds before you engage. Most attacks depend on you moving faster than you can think. That’s the habit Take9 is built around, and it’s quite helpful against these attacks.
Enable two-step login (MFA) on every account and remote access tool, using an authenticator app or security key rather than codes via text message.
Verify before you act. If you receive any unexpected request for anything sensitive or asking for user credentials, stop and contact that person or organization through a secondary channel, using the number or address you already know.
Ask your IT team to limit who can reach your staff on Teams from outside your organization, and allow only one remote support tool your organization actually uses.
Proactively tell voters and candidates where to find official information. Fraudulent sites lose their power when people know the real source.
Make reporting easy. Confirm everyone knows where to report suspicious activity, including your IT support, and build a culture of reporting in your organization. If attacked, employees should not feel ashamed; they are victims.
Agree on a verification step for unusual requests. AI is making social engineering harder to detect and easier for malicious actors to target individuals or offices. Set a simple rule now: any request involving credentials, system access, or sensitive information gets a call back on a known number before anyone acts.
Make your office harder to impersonate. Move your website and email to a.gov domain and ask your IT team to set up email authentication (SPF, DKIM, and DMARC) so attackers can’t send messages that appear to come from your domain.